← All guides Recruitment

AI headshots in recruitment: where it matters

A generated profile photo is usually harmless. A generated identity document is not. How to tell which problem you have, and where checking crosses a legal line.

· 8 min read · Best AI Image Detector

AI headshots are now normal and mostly harmless. The risk is identity verification: right-to-work documents, remote onboarding and proof-of-identity photos, where a generated image has real consequences.

Why an AI headshot is usually not a problem

Generated and enhanced professional headshots have become ordinary. Services that turn a few selfies into studio portraits are cheap, widely advertised and used by people who cannot justify a photographer.

A candidate using one is doing what candidates have always done with lighting, retouching and a borrowed jacket. It is presentation, not deception, and treating it as a red flag will disadvantage people on the basis of what they could afford.

Where it genuinely matters

The risk is not the CV photograph. It is every point where an image is used as evidence of who somebody is.

  • Right-to-work and identity documents. A passport or ID photographed for a remote check. A generated or altered document has legal consequences for the employer as well as the applicant.
  • Selfie-to-document matching. Remote onboarding flows comparing a live photo against an ID. Both sides of that comparison can be synthetic.
  • Proof of address and supporting documents. Utility bills and bank statements, which are easier to fabricate than passports and checked less carefully.
  • Qualification certificates. Photographed or scanned credentials, where an altered name or grade sits in one small region of a genuine document.
  • Contractor and agency worker checks. Often the weakest link, because verification is delegated and inconsistently applied.

The pattern in the last three is the same one that appears in claims and expenses: a real document with one part changed. That is a region-map finding rather than a whole-frame one.

12 15 9 11 14 87 16 10 13 8 12 15

The paper, the lighting and the layout are genuine. One tile covering a data field is not.

A genuine document photographed normally, with one field altered. The whole-frame score was 29.

Why upload is the wrong default here

Identity documents are among the most sensitive personal data an employer handles. Sending a candidate passport to a third-party scoring service creates a processing relationship covering special category data in some jurisdictions, requiring a contract, a lawful basis and a retention position.

A browser-based check avoids the question entirely. The file is read from disk by the page and never transmitted, so there is no processor to appoint and nothing new to add to a privacy notice. For most HR teams that is the difference between using a check and abandoning the idea in procurement.

Where checking crosses a line

Automated screening of candidates carries obligations in many jurisdictions, and image checking sits closer to that boundary than people assume.

What is defensible and what is not
PracticeDefensible?Why
Checking identity documents at right-to-work stageYesA recognised control applied to everyone equally
Checking every candidate photo before shortlistingNoScreening on presentation, unequal in effect
Flagging a document for a human to reviewYesThe decision stays with a person
Rejecting an application on a scoreNoAutomated decision-making with a legal effect
Keeping scores against named applicantsWith careCreates a profile requiring its own basis and retention
Telling candidates checks happenYesUsually required, and it reduces disputes

What to do instead of screening photos

  1. Apply checks at the identity stage only

    Right-to-work and onboarding, where verification is expected and applied to everyone. Not at application, where it becomes a filter on presentation.

  2. Ask for the original document file

    Photographed directly rather than forwarded through email or a chat app. Recompression is the main cause of false positives on document photographs.

  3. Use a live video step for identity

    A short call verifying the person against the document defeats almost every version of this problem and is now standard in remote onboarding.

  4. Route a flag to a person

    A high score means ask again, not reject. Most flags on genuine documents resolve when a better copy arrives.

  5. Say in the privacy notice that checks happen

    Candidates who know accept it. Candidates who find out during a rejection do not, and that is where complaints come from.

What good practice looks like in a hiring process

The teams handling this sensibly have written the rule down rather than leaving it to whoever opens the application. Three decisions do most of the work.

Decide the stage. Identity verification, not application review. Applying a check earlier turns a fraud control into a screening filter, which is where both the fairness problem and the legal exposure come from.

Decide the response. A flag means request a better copy or move to a video check, never a rejection. Writing that down protects the process from an individual recruiter improvising under time pressure.

Decide what is kept. The outcome of the check belongs with the right-to-work record under the same retention period. A separate log of scores against named applicants is a profiling exercise that needs its own justification and rarely has one.

Written down, those three decisions take a short paragraph in a hiring policy. They also remove most of what a rejected candidate could later argue about how their photograph was treated.

Questions people ask

Should we reject candidates with AI-generated headshots?
No. Generated and enhanced professional headshots are ordinary now, and using one says nothing about a candidate except that they did not hire a photographer. Screening on this penalises people by budget and creates a discrimination risk without addressing any real fraud.
Can we detect a fake identity document?
Sometimes, and specifically the common case of a genuine document with one field altered, which shows as a single hot region. A wholly generated document scores high across every tile. Neither result is proof, and both are a reason to ask for a better copy or move to a video check.
Is it legal to run AI detection on candidate documents?
In most places yes, at the identity verification stage, provided the decision stays with a person and candidates are told it happens. It becomes a problem where a score influences an outcome automatically, which several jurisdictions regulate specifically. Ask your own legal team.
Why did a genuine passport photo score high?
Document photographs are taken in poor light, at an angle, on a phone, then compressed by whatever system received them. Every one of those pushes a score upward. Ask for the original file from the device before treating a flag as meaningful.
Do we need to tell candidates we check images?
In most jurisdictions with data protection rules, yes, and it is worth doing regardless. A line in the candidate privacy notice covers it, costs nothing, and removes the argument that a check was carried out covertly.
What about video interviews?
That is a different problem needing different tooling. Still image detection does not address live video manipulation, and frame-by-frame checking misses the temporal artefacts that give real-time manipulation away. Treat it separately rather than assuming coverage.